You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure安全默认值启用疑问及Power BI Embedded认证影响咨询

关于Security Defaults启用的疑问及服务主体认证代码说明

问题背景

作为租户管理员,登录Outlook、Power BI或Azure时,持续收到弹窗提示组织将在2天后自动启用Security Defaults,无直接关闭选项,但当前已在Azure的MS Entra中禁用该功能。有以下两个疑问:

  • 自动启用后能否再次关闭?
  • 当前使用主账户生成访问令牌调用Power BI Embedded APIs/SDK,启用Security Defaults后是否会受影响?

另外计划将代码改为服务主体认证,以下是原代码与修改后代码:

原代码(用户名密码认证)

IPublicClientApplication clientApp = PublicClientApplicationBuilder
                                        .Create(ConfigValidatorService.ApplicationId)
                                        .WithAuthority(m_authorityUrl)
                                        .Build();
var userAccounts = await clientApp.GetAccountsAsync();

SecureString secureStringPassword = new SecureString();
foreach (var key in ConfigValidatorService.Password)
{
    secureStringPassword.AppendChar(key);
}
AuthenticationResult authenticationResult = await clientApp.AcquireTokenByUsernamePassword(m_scope, ConfigValidatorService.Username, secureStringPassword).ExecuteAsync();

修改后代码(服务主体认证)

IConfidentialClientApplication clientApp = ConfidentialClientApplicationBuilder
                                                .Create(ConfigValidatorService.ApplicationId)
                                                .WithClientSecret(ConfigValidatorService.ApplicationSecret)
                                                .WithAuthority(tenantSpecificURL)
                                                .Build();

var authenticationResult = await clientApp.AcquireTokenForClient(m_scope).ExecuteAsync();

解答

1. 自动启用后能否再次关闭?

可以。即便Security Defaults被自动启用,租户管理员仍可在MS Entra管理中心手动关闭该功能。但需注意:如果租户未配置其他符合要求的条件访问策略,关闭后可能再次收到启用提示,建议同步配置自定义条件访问规则替代Security Defaults的安全防护。

2. 启用Security Defaults对当前主账户调用Power BI Embedded APIs的影响

会产生影响。Security Defaults启用后,用户名密码认证(ROPC)方式会被禁用,而当前代码正是采用该方式获取令牌,这会导致调用Power BI Embedded APIs/SDK时认证失败,无法获取有效令牌。

服务主体认证代码说明

你修改后的服务主体认证代码方向正确,Security Defaults启用后不会影响该认证方式(只要服务主体权限配置正确)。需注意以下几点:

  • 确保服务主体已被授予Power BI Embedded所需权限(比如在Power BI管理门户中添加服务主体为工作区管理员,或分配对应应用权限)
  • tenantSpecificURL需替换为租户专属权威URL,格式通常为https://login.microsoftonline.com/{tenant-id}
  • 建议不要直接硬编码客户端密钥,可使用Azure Key Vault等安全方式存储和获取密钥

内容的提问来源于stack exchange,提问作者CSharp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 06:20:56